[30010] in Kerberos

home help back first fref pref prev next nref lref last post

Re: Kinit programatically??

daemon@ATHENA.MIT.EDU (Russ Allbery)
Tue Jun 24 11:18:07 2008

To: "kul gupta" <kulg123@gmail.com>
In-Reply-To: <2203f95e0806240115v358ae905nd3237f08ccfe28b6@mail.gmail.com>
	(kul gupta's message of "Tue\, 24 Jun 2008 13\:45\:14 +0530")
From: Russ Allbery <rra@stanford.edu>
Date: Tue, 24 Jun 2008 08:15:54 -0700
Message-ID: <87bq1qhnit.fsf@windlord.stanford.edu>
MIME-Version: 1.0
Cc: kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

"kul gupta" <kulg123@gmail.com> writes:

> Ya ,actually i framed it in a wrong way.I m really sorry for that.
> I was to ask about fowarding Tickets
> I get the TGT and needs to foward the same to a different target.
> How can i achieve this programatically.?

That is something you can do with GSSAPI.  As part of the negotiation of
the authentication context, you can request ticket delegation, which will
delegate forwardable credentials to the remote host.  See the
documentation for gss_accept_sec_context and gss_init_sec_context.

-- 
Russ Allbery (rra@stanford.edu)             <http://www.eyrie.org/~eagle/>
________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post